CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,693)
page 29 of 85| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-14454 | Med | 0.40 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008. | ||
| CVE-2020-14446 | — | Med | 0.40 | 6.1 | 0.01 | Jun 18, 2020 | An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists. | |
| CVE-2020-3337 | Med | 0.40 | 6.1 | 0.01 | Jun 18, 2020 | A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An… | ||
| CVE-2020-1323 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'. | ||
| CVE-2020-1220 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'. | ||
| CVE-2020-13486 | Med | 0.40 | 6.1 | 0.01 | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. | ||
| CVE-2020-13121 | Med | 0.40 | 6.1 | 0.03 | May 16, 2020 | Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. | ||
| CVE-2020-5409 | Med | 0.40 | 6.1 | 0.01 | May 14, 2020 | Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access… | ||
| CVE-2020-12699 | Med | 0.40 | 6.1 | 0.01 | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. | ||
| CVE-2020-3311 | Med | 0.40 | 6.1 | 0.01 | May 6, 2020 | A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker… | ||
| CVE-2020-3178 | Med | 0.40 | 6.1 | 0.01 | May 6, 2020 | Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of… | ||
| CVE-2020-11034 | Med | 0.40 | 6.1 | 0.08 | May 5, 2020 | In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6. | ||
| CVE-2019-4209 | Med | 0.40 | 6.1 | 0.01 | May 1, 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks. | ||
| CVE-2020-5733 | Med | 0.40 | 6.1 | 0.01 | Apr 17, 2020 | In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information. | ||
| CVE-2020-5732 | Med | 0.40 | 6.1 | 0.01 | Apr 17, 2020 | In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators. | ||
| CVE-2020-11665 | Med | 0.40 | 6.1 | 0.02 | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks. | ||
| CVE-2020-11664 | Med | 0.40 | 6.1 | 0.01 | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks. | ||
| CVE-2020-11663 | Med | 0.40 | 6.1 | 0.01 | Apr 15, 2020 | CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks. | ||
| CVE-2020-3954 | Med | 0.40 | 6.1 | 0.01 | Apr 15, 2020 | Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. | ||
| CVE-2020-6215 | Med | 0.40 | 6.1 | 0.02 | Apr 14, 2020 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL… |
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An…
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.01
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
- risk 0.40cvss 6.1epss 0.03
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
- risk 0.40cvss 6.1epss 0.01
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access…
- risk 0.40cvss 6.1epss 0.01
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker…
- risk 0.40cvss 6.1epss 0.01
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of…
- risk 0.40cvss 6.1epss 0.08
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
- risk 0.40cvss 6.1epss 0.01
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
- risk 0.40cvss 6.1epss 0.01
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information.
- risk 0.40cvss 6.1epss 0.01
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.
- risk 0.40cvss 6.1epss 0.02
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- risk 0.40cvss 6.1epss 0.01
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- risk 0.40cvss 6.1epss 0.01
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
- risk 0.40cvss 6.1epss 0.01
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
- risk 0.40cvss 6.1epss 0.02
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL…